High-level statements of what SFA must achieve to keep information secure; each policy sets the objectives that its supporting standards put into practice.

Articles (4)

Information Security Organization, Personnel & Privacy Policy (SFA 06-107.1)

Sets SFA's objectives for governing the security program and protecting its people, vendors, data, and privacy, including awareness and training, acceptable use, AI governance, and research security; carried out by Standards 06-107.1.1 through 06-107.1.6.

Information Security Technology Policy (SFA 06-107.2)

Sets SFA's objectives for the technical safeguards that protect its systems, devices, and data, covering access, asset management, system development, continuity and disaster recovery, security monitoring, and incident response; carried out by Standards 06-107.2.1 through 06-107.2.6.

Information Security Physical & Environmental Policy (SFA 06-107.3)

Sets SFA's objectives for protecting the facilities, equipment, and environmental controls that support its information systems; carried out by the Physical and Environmental Security Standard (06-107.3.1).

Third-Party & Vendor Risk Management Policy (SFA 06-107.4)

Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.